T03 · Remote Payload Retrieval and Execution
- Location
scripts/install-epm.py:21- Finding
Remote Installer Is Executed Without Integrity or Publisher Verification
- Content
View full analysis
bool: for host in ("d1", "d2", "d3"): if output_path.exists(): output_path.unlink() print(f"Trying mirror {host}...") url = f"https://{host}.easeus.com/epm/free/epm_free_ob.exe?source=skills&dest={dest_arg}" try: with urllib.request.urlopen(url, timeout=60) as response, output_path.open("wb") as fh: fh.write(response.read()) if output_path.exists(): return True ``` ```python print("[1/2] Downloading installer...") if not download_installer(dest_arg, dest_path): print("Download failed from all mirrors.") return 1 if not dest_path.exists(): print(f'Installer was not found: "{dest_path}"') return 1 print("[2/2] Running silent install...") proc = subprocess.run( [ str(dest_path), "/verysilent", "/suppressmsgboxes", "/norestart", "/log", ], check=False, ) ``` ### Technical Analysis The script downloads a Windows executable from one of three external mirrors and executes it immediately in silent mode. It only verifies that the destination file exists; it does not verify a cryptographic digest, an Authenticode signature, the expected publisher, the installer version, the response content type, or the final URL after redirects. HTTPS protects the connection in transit under normal conditions, but it does not establish that the retrieved binary is the exact artifact reviewed or approved by the project. The effective executable payload can change independently after the skill package has been audited. A compromised vendor mirror, CDN, signing or relea ...[truncated 1667 chars]- Remediation
View remediation
